CVE-2026-18577
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A
- EPSS probability
- 54.07%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-288
- Published
- 2026-08-02
- Last modified
- 2026-08-04
Affected products
- N-able N-central
- N-able N-central
Weakness type
Related vulnerabilities
- CVE-2026-88260 — Authentication bypass using an alternate path or channel and Improper validation of syntactic...
- CVE-2026-81906 — [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
- CVE-2026-81796 — WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability
- CVE-2026-81787 — WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability
- CVE-2026-81783 — WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerability
- CVE-2026-88861 — Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization
- CVE-2026-86084 — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
- CVE-2026-83527 — An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a...